Bruce Schneier | |||||||||||||||
Schneier on SecurityA blog covering security and security technology. « UK Border Security | Main | Fingerprinting Paper » August 12, 2005TSA and SpamA reader sent this to me. He's corresponding with the TSA about getting his name off the watch list, and was told that he should turn off his e-mail spam filter. -----Original Message----- Posted on August 12, 2005 at 8:15 AM • 21 Comments To receive these entries once a month by e-mail, sign up for the Crypto-Gram Newsletter. I don't really see anything special about this. "Turn off your spam filter" is standard advice for anybody sending out automated e-mails, which are often caught by spam filters. It's impractical, but then spam is making e-mail itself more and more impractical as time goes by. Posted by: Michael Ash at August 12, 2005 8:39 AM The better warning is "future emails will be coming from monkey@tsa.dot.gov. Please add this email address to your white list." Posted by: Xavier Ashe at August 12, 2005 9:02 AM 'I don't really see anything special about this. "Turn off your spam filter" is standard advice for anybody sending out automated e-mails' Shouldn't the advice be to whitelist the TSA sender address? Posted by: Average Joe #1 at August 12, 2005 9:05 AM If you don't receive this message, please disable your Spam filter. Posted by: Ab Surd at August 12, 2005 9:27 AM Yes. Sadly, there isn't anything really special about this. Posted by: Bruce Schneier at August 12, 2005 9:40 AM Hmm, Bruce - we can't see the content of the angle brackets in the FROM: line above (it shows in the RSS feed). It should, I think, read like this: That's an illegal header syntax. Our mailer will respond like this: So, it's bad advice - but the recipient won't get it because the spam filter is going to reject it! Posted by: Ian Eiloart at August 12, 2005 9:48 AM Opportunities for social engineering abound. The mail should have said to whitelist monkey@tsa.dot.gov as someone else posted. Otherwise spammers will send out official-looking notices asking people to disable spam filters. Posted by: David F. Skoll at August 12, 2005 11:29 AM The "whitelist" suggestions are good, but my assumption is that most people have no idea what a whitelist is. Posted by: Bruce Schneier at August 12, 2005 11:55 AM Is this the person's first contact to the TSA? If so, then perhaps, an auto-responder is necessary. Although I agree with comments suggesting that someone "downgrade" their security profile, by turning of SPAM filters, is not the correct approach. However, the comments were "He's corresponding with the TSA about getting his name off the watch list". If this TSA email is the result of actual correspondence about watch list removal, not first contact, I have to wonder how much "churn" is taking place on the TSA watch list that the TSA needs an auto-responder to handle the volume. Posted by: Whatsup at August 12, 2005 12:35 PM Sounds like the TSA automated response is confusing "watch list" with "spam list" Posted by: martin at August 12, 2005 1:53 PM Call me paranoid, but two possibilities occur to me. 1) This is someone spoofing a TSA email, and 2) the TSA wants to be able to deliver a payload ("we recommend that Spam filters be disabled and that your email account have ample space to receive large files and/or attachments") through which to monitor the corespondent. Either possibility is unsettling. Posted by: carmudgeon at August 12, 2005 3:16 PM "Call me paranoid, but two possibilities occur to me. 1) This is someone spoofing a TSA email." Looks like it. TSA is currently a part of the Department of Homeland Security (dhs.gov) and not the Department of Transportation (dot.gov). Of course, it's possible that someone forgot to change the address. Posted by: Chung Leong at August 12, 2005 3:54 PM @carmudgeon I agree. What's up with the comment about large file attachments, why can't they just provide a link to the documents on their website? What's next... "To ensure timely opening of large file attachments in email responses received from the TSA Contact Center, we recommend disabling anti-virus scanning programs..." Posted by: Whatsup at August 12, 2005 3:55 PM > spam is making e-mail itself more and more impractical as time goes by. email is dead, just like USENET. They're both kicking vigorously at the moment, though. Posted by: Senji at August 12, 2005 4:10 PM Well, I guess the e-mail is authentic. As a test, I sent a e-mail to TSA-ContactCenter@dhs.gov and got the same automated reply, tsa.dot.gov and all. That's just sad. Posted by: Chung Leong at August 12, 2005 4:21 PM Regardless of technical details, the attitude here is entirely typical: They want him to reduce his own security, for *their* purposes. Also known as, "bend over and take it". This fits right in with declaring people "suspicious characters" for objecting to full-body searches by strangers, and their other varied abuses and idiocies. Posted by: David Harmon at August 13, 2005 7:15 AM Not half as retarded as Time Warner insisting that I bypass my hardware firewall before they would send a tech out to diagnose my cable line problem, even though the cable modem itself was throwing hundreds of sync errors every hour. Apparently, they don't trust their tech support reps to decide if it's clear that the problem isn't on the LAN side. Posted by: x at August 13, 2005 8:00 PM Hello, QUESTION?? I can't find any info Posted by: Susie at August 12, 2008 8:23 AM 1. The email addres is probably old and emails to this DOT get forwarded to DHS, pretty standard procedure used when a government body is moved from one sector to another. 2. it is normal for the turn off your spam filter message from any company of government agency you request assistance from (Blame the hackers and spammers) Though few companys handle this correctly, ie ask you to add their email address to your "safe" or address book. 3. You were already upset because some terrorist either shares your name or has possibly used it as an alias, it sucks, its a huge inconvienience but sometime you just have to suck it up and deal with the cards you were dealt. Posted by: mike at November 15, 2008 1:41 PM In early 2007, I boarded a plane in Toronto and flew to cincinnati. Posted by: Jim Fisher at December 10, 2009 11:03 AM Post a comment
Powered by Movable Type. Photo at top by Steve Woit.
Schneier.com is a personal website. Opinions expressed are not necessarily those of BT. |
|
Comments